PT-2017-7408 · Puppet · Puppet Enterprise

Published

2017-12-11

·

Updated

2022-01-24

·

CVE-2015-8470

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Puppet Enterprise versions 3.7.x through 3.8.x and 2015.2.x
Description The issue is related to the console in Puppet Enterprise not setting the secure flag for the JSESSIONID cookie in an HTTPS session. This makes it easier for remote attackers to capture the cookie by intercepting its transmission within an HTTP session.
Recommendations For Puppet Enterprise versions 3.7.x, 3.8.x, and 2015.2.x, consider updating the configuration to set the secure flag for the JSESSIONID cookie in HTTPS sessions to prevent interception. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8470

Affected Products

Puppet Enterprise